Re: Harvest netblocks of good MTAs from SPF for whitelisting from greylisting

Stuart D Gathman <[email protected]> Tue, 12 Feb 2013 20:50:01 -0500
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <[email protected]>
On 02/12/2013 07:19 PM, Constantine A. Murenin wrote:
> No.  I cannot have my firewall do SPF evaluations, and I'm not
> attempting to do the same thing as SPF.  I am also not guessing valid
> MTAs, I'm getting their list deterministically based on static SPF
> information that is published by relevant entities whose mail I might
> care to never delay.
>
You misunderstood.  My only suggestion was to calculate the *actual* IP 
set, not the "netblock" set.  SPF is much more fine grained than 
netblocks.  The same colocation facility might have both "good" and 
"evil" domains.  The idea of statically compiling the IP set for your 
type of application is a good one, and has already been implemented.